Skip to content
arrow_back
ISM-0459policyASD Information Security Manual (ISM)

Implement Full or Partial Disk Encryption

Use encryption to protect data on disks, ensuring all writings are to encrypted areas only.

record_voice_over

Plain language

This control ensures that all data stored on your computer's hard drive is encrypted, meaning it's scrambled in a way that only someone with the right password can unscramble and read it. This is important because if a device gets lost or stolen, without encryption, anyone could access sensitive information stored on it.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Full disk encryption, or partial encryption where access controls only allow writing to encrypted partitions or volumes, is implemented when encrypting media.
policyASD Information Security Manual (ISM)ISM-0459
priority_high

Why it matters

If not encrypted, lost or stolen devices can lead to data breaches, exposing confidential information and harming business reputation.

settings

Operational notes

Regularly verify that encryption is active on all devices and conduct refresher training on password best practices to maintain data security.

build

Implementation tips

  • IT Team: Ensure full or partial disk encryption is enabled on all computers and servers. Use built-in tools like BitLocker for Windows or FileVault for Mac to encrypt data on disks.
  • System Administrator: Regularly check that encryption is active on all devices by reviewing system settings. This can often be found under 'Security' or 'System Preferences'.
  • Aska checklist that shows this has been completed
  • Training Officer: Develop a simple guide for staff explaining how to set strong passwords for devices and why it's crucial for the security of encrypted data. Conduct regular training sessions to reinforce this.
  • Procurement Officer: When purchasing new devices, specify in the requirements that they must support encryption. Verify this feature before finalizing any contracts with suppliers.
fact_check

Audit / evidence tips

  • Aska list of all devices that are encrypted. Verify that each device, especially those that store sensitive information, is included in this list
  • Look atthe dates and findings from these audits to ensure encryption is consistently checked
  • Goodincludes a completed checklist for each device
  • Askthe staff training schedule and materials on encryption and password managementLook atregular training dates and clear, easy-to-understand guides
  • Request purchasing agreements for IT equipment to check for encryption support clauses. A well-defined agreement will specify encryption requirements.
link

Cross-framework mappings

How ISM-0459 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.24ISM-0459 requires implementing full disk encryption, or partial disk encryption where controls ensure data can only be written to the enc...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for media controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls